CVE-2017-0914
Severity
7.5HIGH
EPSS
0.2%
top 61.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 21
Latest updateMay 13
Description
Gitlab Community and Enterprise Editions version 10.1, 10.2, and 10.2.4 are vulnerable to a SQL injection in the MilestoneFinder component resulting in disclosure of all data in a GitLab instance's database.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6
Affected Packages2 packages
▶CVEListV5gitlab/gitlab_community_and_enterprise_editions10.2.0 - 10.2.5 Fixed in 10.2.6, 10.3.0 - 10.3.3 Fixed in 10.3.4, 9.1.0 - 10.1.5 Fixed in 10.1.6+2
🔴Vulnerability Details
2📋Vendor Advisories
2GitLab▶
CVE-2017-0914: Gitlab Community and Enterprise Editions version 10.1, 10.2, and 10.2.4 are vulnerable to a SQL injection in the MilestoneFinder component resulting i↗2018-03-21
Debian▶
CVE-2017-0914: gitlab - Gitlab Community and Enterprise Editions version 10.1, 10.2, and 10.2.4 are vuln...↗2017